> If I accidentally log IP addresses for EU users that opted out
If opting out is a possibility, then it's not essential data. If it's not essential data, what legitimate reason would you have to collect it in the first place?
Data safety is a not a binary thing (essential = okay to keep, non-essential = not okay). Instead , it is a context-sensitive, layered, multi-axis concern. IP addresses, for instance, are PII that are essential for network routing, but that doesn't mean address+based ad retargeting is fair game.
Accidentally logging data that's essential but was supposed to be ephemeral would turn it "not-ephemeral" and make it possible to cross-reference with other information in privacy-defeating ways. As I said, it was a privacy-focused product, and using data that is meant for one thing (e.g. abuse detection and prevention) for some other out-of-spec use - even accidentally - is a big no-no.
If opting out is a possibility, then it's not essential data. If it's not essential data, what legitimate reason would you have to collect it in the first place?